Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Users] Static virtual ip address

From: Andreas Steffen <andreas.steffen(at)strongsec.net>
Date: Wed Feb 19 2003 - 17:18:53 EST

Chris Ehlers wrote:
> After further inverstigation I found that freeswan i found that I misspelled

No, kicking out the connection is not the default behaviour. Instead an error message is written to the log that the certificate and with it the ID could not be loaded

 > Feb 19 17:48:41 VPN2 pluto[2783]:   could not open host cert file
 > '/etc/ipsec.d/certs/test2-cert.pem' #PROBLEM
 > Feb 19 17:48:41 VPN2 pluto[2783]: added connection description "test2"

but the following anonymous connection is created

conn test2

	right=%any
	leftsubnet=172.30.0.0/16
	rightsubnet=172.30.0.5/32

This means that anyone with a valid certificate issued by a trusted CA can connect when the subnets match this definition.

Recommendation: When setting up new connection definitions always check what actually has been loaded, using

    ipsec auto --status

Do you need help?X

Regards

Andreas


Andreas Steffen                   e-mail: andreas.steffen@strongsec.com
strongSec GmbH                    home:   
http://www.strongsec.com
Alter Zürichweg 20                phone:  +41 1 730 80 64
CH-8952 Schlieren (Switzerland) fax: +41 1 730 80 65
==========================================[strong internet security]===


_______________________________________________
Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Thu Feb 20 06:15:38 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:21 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library